Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OXLOADER Exploits Malicious Ads to Spread CastleStealer

OXLOADER Exploits Malicious Ads to Spread CastleStealer

Posted on June 22, 2026 By CWS

Cybersecurity experts have revealed a new wave of cyberattacks involving a malware loader known as OXLOADER. This tool is employed to distribute CastleStealer, a type of information-stealing malware. The campaign, uncovered by Elastic Security Labs, features the use of deceptive Google Ads to initiate the malware distribution process.

Malicious Ads Fuel Cyber Threat

The campaign, identified as REF8372, employs malicious advertisements to lure victims. Researchers suggest the individuals behind the attack may be Russian-speaking and financially driven, as they avoid targeting systems in the Commonwealth of Independent States (CIS). The campaign’s sophisticated techniques include control-flow flattening and mixed Boolean-Arithmetic to obscure the malware’s presence.

Users searching for terms like “lts version of node.js” may inadvertently access a counterfeit site through fraudulent ads. The ads, falsely attributed to a Ukrainian entity, “ВОЛОДИМИР ТЕРЕЩЕНКО,” were removed by Google on May 14, 2026. Whether this advertiser account is directly linked to the attackers or a front remains unclear.

Unveiling the Attack Methodology

The attack initiates when users interact with the fraudulent site, leading to the download of a batch script hosted on Storj, a decentralized storage service. This method illustrates the ongoing exploitation of legitimate platforms to bypass security filters. The script launches a fake installation wizard while covertly downloading and executing OXLOADER via a PowerShell command, triggering a User Account Control (UAC) prompt.

Further complicating detection, the attack uses DLL side-loading to deploy a rogue DLL, which decrypts and runs the CastleStealer payload. Techniques such as control-flow flattening and mixed Boolean-Arithmetic are employed to avoid detection, while anti-VM measures ensure the malware does not run in sandbox environments.

Implications and Future Monitoring

CastleStealer, a .NET-based information stealer, is part of a broader campaign known as BackgroundFix, previously linked with CastleLoader. The activity is associated with a threat group identified as GrayBravo. Despite being in its early stages, OXLOADER’s sophisticated design indicates potential for significant impact.

Elastic Security Labs emphasizes that the malware’s engineering reflects deliberate efforts to evade detection and analysis. This has resulted in low detection rates across various security engines, allowing OXLOADER to operate under the radar. The cybersecurity community is advised to keep a close watch on this evolving threat.

The Hacker News Tags:CASTLESTEALER, control-flow flattening, cyber threats, Cybersecurity, Elastic Security Labs, Google Ads, information stealer, Malvertising, Malware, OXLOADER

Post navigation

Previous Post: WhatsApp Malware Targets Windows Users Globally
Next Post: Critical Squid Proxy Flaw ‘Squidbleed’ Exposes User Data

Related Posts

Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment Anubis Ransomware Encrypts and Wipes Files, Making Recovery Impossible Even After Payment The Hacker News
Weekly Cybersecurity Update: Major Breaches and Vulnerabilities Weekly Cybersecurity Update: Major Breaches and Vulnerabilities The Hacker News
Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit Meta to Train AI on E.U. User Data From May 27 Without Consent; Noyb Threatens Lawsuit The Hacker News
Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File Microsoft OneDrive File Picker Flaw Grants Apps Full Cloud Access — Even When Uploading Just One File The Hacker News
Meta Thwarts NSO Group’s WhatsApp Phishing Scheme Meta Thwarts NSO Group’s WhatsApp Phishing Scheme The Hacker News
Enhancing Security with Ceros for Claude Code Enhancing Security with Ceros for Claude Code The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Mandates Developer Verification for Android in Four Nations
  • Critical Squid Proxy Vulnerability Exposed with AI Assistance
  • Fortinet Addresses FortiBleed Threat to Firewalls
  • Squid Proxy Vulnerability ‘Squidbleed’ Exposes HTTP Requests
  • QNAP Addresses Critical NAS Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Mandates Developer Verification for Android in Four Nations
  • Critical Squid Proxy Vulnerability Exposed with AI Assistance
  • Fortinet Addresses FortiBleed Threat to Firewalls
  • Squid Proxy Vulnerability ‘Squidbleed’ Exposes HTTP Requests
  • QNAP Addresses Critical NAS Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark